VulnSea

stdlib has 17 CVEs on record between 2022 and 2026. Disclosure cadence is accelerating: 5 in the last 90 days against 3 in the 90 before. The busiest recent month was August 2026 with 5. The median CVSS is 7.5 (high). None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
Last 90 days
5 prev 3

Products

  • stdlib 17
17
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

stdlib vulnerabilities

CVEs affecting stdlib, newest first. Open any entry for full detail, references, and exploit status.

17 CVEsRSS

CVE-2026-56860High· 7.5
1mo ago

Avoid quadratic complexity in resolvePath in net/url

Avoid quadratic complexity in resolvePath in net/url

Twilightstdlib · stdlibEPSS 0.52%via OSV
CVE-2026-56858High· 8.1
1mo ago

Fix Javascript regexp context tracking in html/template

Fix Javascript regexp context tracking in html/template

Twilightstdlib · stdlibEPSS 0.31%via OSV
CVE-2026-56862High· 7.5
1mo ago

Limit handshake messages we are willing to accept post-handshake in crypto/tls

Limit handshake messages we are willing to accept post-handshake in crypto/tls

Twilightstdlib · stdlibEPSS 0.57%via OSV
CVE-2026-56859High· 7.5
1mo ago

Add recursion depth guard during decode in encoding/xml

Add recursion depth guard during decode in encoding/xml

Twilightstdlib · stdlibEPSS 0.57%via OSV
CVE-2026-33818High· 7.5
1mo ago

Enforce maximum recursion depth in encoding/asn1

Enforce maximum recursion depth in encoding/asn1

Twilightstdlib · stdlibEPSS 0.57%via OSV
CVE-2026-42504High· 7.5
3mo ago

Quadratic complexity in WordDecoder.DecodeHeader in mime

Quadratic complexity in WordDecoder.DecodeHeader in mime

Twilightstdlib · stdlibEPSS 0.56%via OSV
CVE-2026-39836None
4mo ago

Panic in Dial and LookupPort when handling NUL byte on Windows in net

Panic in Dial and LookupPort when handling NUL byte on Windows in net

Sunlitstdlib · stdlibEPSS 0.59%via OSV
CVE-2026-32281Medium· 5.9
5mo ago

Inefficient policy validation in crypto/x509

Inefficient policy validation in crypto/x509

Sunlitstdlib · stdlibEPSS 0.36%via OSV
CVE-2025-68121None
7mo ago

Unexpected session resumption in crypto/tls

Unexpected session resumption in crypto/tls

Sunlitstdlib · stdlibEPSS 0.78%via OSV
CVE-2025-61728None
7mo ago

Excessive CPU consumption when building archive index in archive/zip

Excessive CPU consumption when building archive index in archive/zip

Sunlitstdlib · stdlibEPSS 0.68%via OSV
CVE-2025-61729None
9mo ago

Excessive resource consumption when printing error string for host certificate validation in crypto/x509

Excessive resource consumption when printing error string for host certificate validation in crypto/x509

Sunlitstdlib · stdlibEPSS 0.46%via OSV
CVE-2025-58183None
10mo ago

Unbounded allocation when parsing GNU sparse map in archive/tar

Unbounded allocation when parsing GNU sparse map in archive/tar

Sunlitstdlib · stdlibEPSS 0.41%via OSV
CVE-2024-34158None
2y ago

Stack exhaustion in Parse in go/build/constraint

Stack exhaustion in Parse in go/build/constraint

Sunlitstdlib · stdlibEPSS 1.0%via OSV
CVE-2022-41715None
3y ago

Memory exhaustion when compiling regular expressions in regexp/syntax

Memory exhaustion when compiling regular expressions in regexp/syntax

Sunlitstdlib · stdlibEPSS 1.4%via OSV
CVE-2022-2880None
3y ago

Incorrect sanitization of forwarded query parameters in net/http/httputil

Incorrect sanitization of forwarded query parameters in net/http/httputil

Sunlitstdlib · stdlibEPSS 1.2%via OSV
CVE-2022-2879None
3y ago

Unbounded memory consumption when reading headers in archive/tar

Unbounded memory consumption when reading headers in archive/tar

Sunlitstdlib · stdlibEPSS 1.7%via OSV
CVE-2022-32190None
4y ago

Failure to strip relative path components in net/url

Failure to strip relative path components in net/url

Sunlitstdlib · stdlibEPSS 2.2%via OSV
stdlib vulnerabilities (CVEs) · VulnSea